Introduction

IFA Connect Ltd (company no. 15993861) (“IFA Connect”, “we”, “us”) is committed to protecting your privacy and ensuring your personal data is handled securely and responsibly. This Privacy Policy explains the data we collect, how we use and share it, how we use artificial intelligence, and your rights under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

It covers our public website (www.ifaconnect.co.uk), our online matching assistant, telephone calls with our team, and our adviser portal (app.ifaconnect.co.uk).

IFA Connect is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO) under reference ZB918058.

Who this policy applies to

This policy applies to two groups of people:

  • Clients: individuals seeking financial advice who ask us to introduce them to an adviser.
  • Advisers: FCA-regulated Independent Financial Advisers who register on our portal to receive client introductions.

Where your information comes from

We obtain your information from you directly: through the enquiry forms on our website, our online matching assistant, telephone calls with our team, and bookings made through Calendly. Where you arrive at our website from an advert on Meta (Facebook or Instagram) or Google, we also receive the click identifier those platforms attach to the link. We do not buy personal data about clients from third parties.

What data we collect

Client data (collected during the enquiry and matching process): name, email address, phone number, age, occupation, town and region, the type of advice you are looking for, approximate pension, ISA and investment values and providers, income goals for retirement, family situation and financial goals, when you would like to start and whether you already have an adviser, anything you tell us in the free-text part of a form or on a call, and which page or advert brought you to us.

Call recordings and transcripts of calls between you and our team, and the AI-generated summary of each call. See Call recording below.

Adviser data (collected during registration and portal use): name, email address, phone number, firm name, FCA number, region, payment and billing information (processed by Stripe, not stored by us directly), credit purchase and transaction history.

Technical data (collected automatically): IP address, browser type and version, authentication session data, and the cookies that are strictly necessary for the website and portal to work. With your consent, advertising cookies and identifiers set by Meta and Google (see Cookies).

Lawful basis for processing

We process personal data on the following legal bases:

  • Contract: to provide our matching and introduction service to both clients and advisers.
  • Legitimate interests: to operate, secure and improve the website and portal, prevent fraud, administer adviser accounts, prepare an accurate record of your enquiry (including recording calls), and retain a record of the introduction made in order to evidence consent and defend potential claims.
  • Consent: to share your details with a financial adviser you have asked to be introduced to; to set advertising cookies and to share hashed contact details with Meta for advertising measurement; and for marketing communications where applicable. Where you choose to tell us about your health, we rely on your explicit consent (see Health and other sensitive information).
  • Legal obligation: to comply with tax and company law record-keeping obligations.

How we use your data

  • Matching clients with advisers: to connect clients with FCA-regulated financial advisers suited to their needs.
  • Preparing your profile: to write a summary of your enquiry so the adviser understands your situation before contacting you. See How we use artificial intelligence.
  • Communication: to contact clients by email or phone about their enquiry, and to send advisers transactional notifications including lead alerts, purchase confirmations and account updates.
  • Portal operation: to manage adviser accounts, process credit purchases and provide customer support.
  • Security: to protect accounts through two-factor authentication, rate limiting and fraud detection.
  • Advertising measurement: with your consent, to understand whether our advertising led to your enquiry (see Cookies).
  • Marketing: with your consent, we may send newsletters, promotional content or information about relevant services. You can withdraw consent at any time.

How we use artificial intelligence

We use AI tools to help our team record and organise the information you give us. AI never decides whether you are introduced to an adviser, and no decision about you is made solely by automated means. A member of our team reviews everything the AI produces.

Specifically:

  • Call notes. Calls with our team are recorded and transcribed by our phone provider, JustCall, whose AI also produces a summary of the call. We use the transcript and summary to prepare your profile accurately.
  • Your profile. We use Anthropic’s Claude to draft a written summary of your enquiry from the call. Our team checks and edits that summary before it is used.
  • Adding you to our portal. When we add your enquiry to our adviser portal, Claude reads the profile document to fill in the form and to tidy the wording. Our team reviews every field before it is saved.
  • Matching assistant. If you use our online matching assistant, your answers are processed by Claude to understand what you are looking for and to suggest suitable advisers.
  • Adviser support. Advisers on our portal can use a Claude-powered assistant for questions about the service. It has no access to client records.

Anthropic processes this information on our behalf under a data processing agreement. It does not use your information to train its models and retains it only briefly for security monitoring. If you would prefer us not to use AI tools on your information, tell us when you enquire or email hello@ifaconnect.co.uk; we will handle your enquiry manually, which may take a little longer.

Call recording

Calls between you and our team are recorded and transcribed so that we can prepare an accurate profile of your needs, train our team and resolve any dispute about what was discussed. We tell you at the start of the call. Recordings and transcripts are stored by our phone provider, JustCall, and deleted after 90 days. You can ask us not to record a call; we will take notes instead.

Health and other sensitive information

We do not ask for information about your health. If you choose to tell us something about your health because it is relevant to the advice you need, for example ill-health retirement, we will record it only with your explicit agreement and only as far as it is needed to find you the right adviser. You can ask us to remove it at any time.

How we share your data

With advisers. Before an adviser purchases your enquiry, vetted advisers on our portal can see an anonymised summary: your region and town, age, the type of advice you need, an outline of your assets and a description of your situation. Your name, email address and phone number are not shown at this stage.

When an adviser purchases your enquiry, that adviser’s firm receives your name and contact details and a copy of the summary, and we email you to introduce them. From that point the adviser firm is responsible for how it uses your information under its own privacy notice. We require advisers to use your details only to respond to your enquiry.

With our service providers. We use the following companies to run our service. Each processes data on our behalf, only on our instructions and under a data processing agreement:

  • Supabase: the database and file storage behind our portal, hosted in the EU or UK.
  • Vercel: hosting for our website and portal. Our code runs in London; Vercel’s logs are held in the United States.
  • Anthropic: the AI processing described above: drafting your profile, reading profile documents into the portal, tidying wording, the matching assistant and the adviser support assistant. United States.
  • JustCall (SaaS Labs): telephone calls, call recording, transcription and AI call summaries. United States.
  • Google Workspace: our team’s email, and the documents in which client profiles are prepared. Data may be stored outside the UK.
  • Monday.com: the system in which our team tracks enquiries.
  • Postmark (ActiveCampaign): email sent from the portal to clients and advisers. United States.
  • Resend: email delivery for website enquiries, confirmation emails and announcements to advisers. United States.
  • Calendly: booking a call with our team (your name, email address, phone number and chosen time). United States.
  • Zapier: the automation that adds the right member of our team to a call you book. United States.
  • Stripe: payment processing for advisers. United States.

With advertising platforms. With your consent, Meta and Google receive information about your visit through cookies, and when you submit an enquiry we send Meta a hashed (irreversibly encoded) version of your contact details so it can tell whether one of our adverts led to the enquiry. Meta cannot read the details, only match them against its own records. For this measurement Meta and Google act as joint controllers with us under their own terms. If you reject advertising cookies, none of this happens.

We do not sell your data to any third party. Data is only shared as described above and is never distributed to unauthorised third parties.

International data transfers

Several of our service providers are based in the United States: Anthropic, JustCall, Vercel, Postmark, Resend, Calendly, Zapier and Stripe, along with Meta and Google. Google Workspace and Monday.com may also store data outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place.

Stripe and ActiveCampaign (Postmark) are certified under the UK Extension to the EU-US Data Privacy Framework. Our other providers operate under Data Processing Agreements incorporating Standard Contractual Clauses and the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement. A Transfer Risk Assessment covering these transfers is maintained and reviewed annually.

Data retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy:

  • Client enquiry data on our portal and in our CRM: up to 6 years from the date of the enquiry, reflecting the six-year limitation period for claims.
  • Call recordings, transcripts and AI summaries: 90 days, after which JustCall deletes them.
  • Profile documents prepared by our team: up to 6 years, in line with the enquiry they relate to.
  • Team email containing your details: subject to the same six-year limit.
  • Adviser account data: for the duration of the account and for up to 6 years after closure for tax and regulatory compliance.
  • Transaction and billing records: 6 years, in line with HMRC requirements.
  • Technical logs: up to 12 months, for security and debugging.
  • Your cookie choice: kept in your browser until you clear it or change it. Meta and Google keep advertising measurement data under their own policies.

After the retention period, data is securely deleted or anonymised.

Your rights

Under the UK GDPR, you have the following rights:

  • Right to access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you may request corrections to incomplete or inaccurate data.
  • Right to erasure: you have the right to request the deletion of your personal data, subject to our legal retention obligations.
  • Right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
  • Right to data portability: you can request your data in a structured, commonly used format.
  • Right to object: you can object to the processing of your data where we rely on legitimate interests.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time. For advertising cookies, use Cookie settings in the footer of any page.
  • Manual handling: you can ask us to handle your enquiry without AI tools (see How we use artificial intelligence).

To exercise any of these rights, please contact us at hello@ifaconnect.co.uk. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk).

Cookies

Strictly necessary cookies are always on, because the website and portal cannot work without them. On the portal these are session cookies and two-factor authentication tokens. On the website the only strictly necessary storage is the record of your cookie choice.

Advertising and analytics cookies are set only if you choose Accept in the cookie banner. We currently use the Meta Pixel (cookies named _fbp and _fbc) to measure adverts on Facebook and Instagram, and Google Ads with Google Tag Manager (cookies beginning _gcl) to measure Google adverts. Until you choose Accept, no advertising cookie is set and nothing is sent to Meta or Google from your browser. If you choose Reject, nothing loads. We do not currently use analytics cookies; if we add any, they will be covered by the same choice.

Changing your choice. Use Cookie settings in the footer of any page to see the banner again and change your answer. Choosing Reject after Accept removes the advertising cookies we can reach and stops any further loading. You can also delete cookies through your browser settings.

Security measures

We take the protection of your personal data seriously and implement robust security measures, including:

Two-factor authentication (email verification codes and optional TOTP) on all portal accounts. Encrypted sessions using signed JSON Web Tokens. Bcrypt password hashing. Row-level security policies on our database ensuring users can only access data they are authorised to view. Rate limiting on authentication and sensitive endpoints. HTTPS encryption on all connections. Secure, HttpOnly, SameSite cookies to prevent session hijacking. Regular security audits of the portal codebase.

Data held on Monday CRM is protected with multi-factor authentication and access controls.

Data breach procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, in accordance with UK GDPR Articles 33 and 34.

Children’s data

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

Third-party links

Our website and portal may contain links to external websites. We are not responsible for the privacy practices of third-party sites and encourage you to read their privacy policies.

Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically.

Contact information

If you have any privacy-related questions, concerns or requests, please contact us at:

IFA Connect Ltd
Email: hello@ifaconnect.co.uk
ICO Registration: ZB918058

Governing law

This Privacy Policy is governed by and interpreted in accordance with the laws of the United Kingdom.

Last updated: 12 September 2026